VDB
BDU%3A2025-03458
BDU%3A2025-03458
PUBLISHED
CVSS 6.400000095367432 MEDIUM
Уязвимость метода web.static(..., show_index=True) HTTP-клиента aiohttp, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность системы
Risk Scores
CVSS 2.0
6.400000095367432
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Novell Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», Red Hat Inc. | OpenSUSE Leap, openSUSE Tumbleweed, SUSE Linux Enterprise Module for Public Cloud, Debian GNU/Linux, РЕД ОС (запись в едином реестре российских программ №3751), SUSE Linux Enterprise High Performance Computing, Suse Linux Enterprise Server, SUSE Linux Enterprise Server for SAP Applications, SUSE Manager Proxy, SUSE Manager Server, SUSE Enterprise Storage, SUSE Manager Retail Branch Server, Suse Linux Enterprise Desktop, Red Hat Update Infrastructure for Cloud Providers, aiohttp, Red Hat Ansible Automation Platform, Red Hat Satellite, SUSE Linux Enterprise Module for Python 3 |
Timeline
- Mar 27, 2025 CVE Published
- Aug 11, 2025 CVE Updated
References
- https://redos.red-soft.ru/support/secure/ url
- https://github.com/aio-libs/aiohttp/commit/28335525d1eac015a7e7584137678cbb6ff19397 url
- https://github.com/aio-libs/aiohttp/pull/8319 url
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-7gpw-8wmc-pm8g url
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ url
- https://security-tracker.debian.org/tracker/CVE-2024-27306 url
- https://access.redhat.com/security/cve/CVE-2024-27306 url
- https://www.suse.com/security/cve/CVE-2024-27306.html url